当前位置:网站首页>F5 big IP Icontrol rest command execution (cve-2022-1388)
F5 big IP Icontrol rest command execution (cve-2022-1388)
2022-06-29 10:19:00 【Qianli ZLP】
One 、 Vulnerability description
2022 year 5 month 6 Japan ,F5 The official website publishes safety announcements , Disclosure F5 BIG-IP There is a Remote Code Execution Vulnerability (CVE-2022-1388). The flaw lies in iControl REST In the component , The vulnerability allows attackers who define authentication to pass BIG-IP Manage the interface and yourself IP The address of iControl REST API Interface for network access , As a result, arbitrary system commands can be executed on the target host 、 Create or delete files or disable BIG-IP Service on .
Components :F5 BIG-IP iControl REST
Hole type : Authentication bypasses
influence : Command execution
sketch : This vulnerability allows an unauthenticated attacker to pass through the management port or self body ip The address of BIG-IP System access , To perform duties Meaning system commands , Create or delete files and disable BIG-IP Service on .
Two 、 scope
BIG-IP 16.x: 16.1.0 - 16.1.2
BIG-IP 15.x: 15.1.0 - 15.1.5
边栏推荐
- Six dimensional space BFS
- 520 diamond Championship 2021
- Gmail: how to quickly read all messages
- L2-026 small generation (25 points)
- acwing271【杨老师的照相排列】【线性DP】
- Wandering -- the last programming challenge
- HDU 6778 car (group enumeration -- > shape pressure DP)
- URAL1517 Freedom of Choice 【后缀数组:最长公共连续子串】
- 子串分值-超详细版——最后的编程挑战
- Sixteen system counter and flow lamp
猜你喜欢
随机推荐
图片验证码控件
基辅周边的凄美废墟——切尔诺贝利的安全前往指南!
1147 Heaps (30 分)
51nod1277 字符串中的最大值【KMP】
L2-026 小字辈 (25 分)
2019.11.13 training summary
JVM之方法的绑定机制
L1-009 N个数求和 (20 分)
Nacos registry cluster
十六制计数器和流水灯
Rikka with cake (segment tree + segment tree)
FreeRTOS (IX) - queue
函数指针、函数指针数组、计算器+转移表等归纳总结
Power Strings【KMP循环节】
2021年团体程序设计天梯赛-模拟赛
2019.10.20 training summary
PGP在加密技术中的应用
Listview of the basic component of the shutter
两个栈的模拟题
L2-025 divide and rule (25 points)







